You don't have to secure everything perfectly. Account safety follows a brutal 80/20 rule: a handful of habits stop almost everything, and skipping them leaves you wide open no matter what else you do. The three that matter most are a unique password for every account (with a manager doing the remembering), a second factor turned on, and your email locked down hardest of all β because whoever controls your email can reset their way into everything else you own.
Your email is the master key
Think about what happens when you forget a password anywhere: the reset link goes to your email. That means your inbox isn't just another account β it's the skeleton key to your bank, your shopping, your social media, everything. Whoever owns your email owns your digital life.
- Give it your strongest, unique password and turn on two-factor (below) β do this one first.
- Check its recovery settings β make sure the backup phone/email are yours and current, not an old number a stranger could claim.
- Look for sneaky forwarding rules β attackers quietly set your mail to auto-forward to them. If you've ever been compromised, check this.
Stop reusing passwords β let a manager remember
Reuse is the number-one cause of account takeover
When any one site gets breached, criminals take those leaked email-and-password pairs and try them everywhere else (it's automated, and it's called credential stuffing). One reused password can unlock a dozen of your accounts.
A password manager makes unique passwords effortless
It generates and stores a different strong password for every site, and fills them in for you. You remember one strong master password; it handles the rest. The ones built into your browser or phone are a fine place to start, and dedicated apps do more.
Turn on two-factor (2FA)
Two-factor means a second step beyond your password β so even if your password leaks, an attacker still can't get in. It's the single biggest upgrade after unique passwords.
- Prefer an authenticator app or a security key over text-message codes where you have the choice β SMS can be hijacked by a SIM-swap (more in the next guide).
- Save your backup codes somewhere safe (in your password manager, or on paper) so you're not locked out if you lose your phone.
- Turn it on for the big ones first β email, bank, and your main accounts β then the rest over time.
Spot a takeover attempt
The other classic move is a fake "unusual sign-in" or "your password was changed" alert with a link that leads to a convincing fake login page. Don't click it β go to the site directly through your own bookmark or app and check there. (Spotting these is the heart of the Hold Your Own scam-defense kit.)
A 20-minute starting plan
- Set up a password manager (browser, phone, or a dedicated app) and pick one strong master passphrase.
- Fix your email first β give it a new unique password and turn on 2FA.
- Then your bank and main accounts β unique password + 2FA on each, a few at a time.
- Save your backup codes somewhere you won't lose them.
- Sign out everywhere unfamiliar β most big accounts have a "where you're logged in" list; boot anything you don't recognize.
Account-security checklist
Tick what's done.
The close
Digital security sounds exhausting, but the part that matters isn't. Three habits β protect your email, use a password manager, turn on two-factor β quietly defeat the attacks that actually happen to ordinary people. Set them up once, mostly in an afternoon, and you go from "one leaked password away from chaos" to a genuinely hard target. You don't need to be paranoid or technical. You need unique passwords, a second factor, and the instinct to never hand over a code. Lock those down, and the rest is details.